Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2016-6391


Cisco IOS 12.2 and 15.0 through 15.3 allows remote attackers to cause a denial of service (traffic-processing outage) via a crafted series of Common Industrial Protocol (CIP) requests, aka Bug ID CSCur69036.


Security Impact Summary

This vulnerability carries a HIGH severity rating with a CVSS v3.1 score of 7.5, indicating it can be exploited remotely over the network with relatively low complexity without requiring user interaction and does not require pre-existing privileges . The vulnerability impacts and availability (service disruption) for affected systems. Impacting 1 product from cisco organizations running these solutions should prioritize assessment and patching.

Historical Context

First disclosed in 2016, this vulnerability was reported during a period defined by widespread IoT adoption challenges, mobile security concerns, and the emergence of advanced persistent threat (APT) techniques. Contemporary mitigation strategies focused on secure development practices and third-party component vetting.


Published

2016-10-05T20:59:06.650

Last Modified

2025-04-12T10:46:40.837

Status

Deferred

Source

[email protected]

Severity

CVSSv3.0: 7.5 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:N/I:N/A:C

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: COMPLETE
Exploitability Score

10.0

Impact Score

6.9

Weaknesses
  • Type: Primary
    CWE-399

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System cisco ios 12.2\(44\)ex Yes
Operating System cisco ios 12.2\(44\)ex1 Yes
Operating System cisco ios 12.2\(46\)se Yes
Operating System cisco ios 12.2\(46\)se1 Yes
Operating System cisco ios 12.2\(46\)se2 Yes
Operating System cisco ios 12.2\(50\)se Yes
Operating System cisco ios 12.2\(50\)se1 Yes
Operating System cisco ios 12.2\(50\)se2 Yes
Operating System cisco ios 12.2\(50\)se3 Yes
Operating System cisco ios 12.2\(50\)se4 Yes
Operating System cisco ios 12.2\(50\)se5 Yes
Operating System cisco ios 12.2\(52\)se Yes
Operating System cisco ios 12.2\(52\)se1 Yes
Operating System cisco ios 12.2\(55\)se Yes
Operating System cisco ios 12.2\(55\)se3 Yes
Operating System cisco ios 12.2\(55\)se4 Yes
Operating System cisco ios 12.2\(55\)se5 Yes
Operating System cisco ios 12.2\(55\)se6 Yes
Operating System cisco ios 12.2\(55\)se7 Yes
Operating System cisco ios 12.2\(55\)se8 Yes
Operating System cisco ios 12.2\(55\)se9 Yes
Operating System cisco ios 12.2\(55\)se10 Yes
Operating System cisco ios 12.2\(58\)se2 Yes
Operating System cisco ios 15.0\(1\)ey Yes
Operating System cisco ios 15.0\(1\)ey1 Yes
Operating System cisco ios 15.0\(1\)ey2 Yes
Operating System cisco ios 15.0\(2\)eb Yes
Operating System cisco ios 15.0\(2\)ey Yes
Operating System cisco ios 15.0\(2\)ey1 Yes
Operating System cisco ios 15.0\(2\)ey2 Yes
Operating System cisco ios 15.0\(2\)ey3 Yes
Operating System cisco ios 15.0\(2\)se Yes
Operating System cisco ios 15.0\(2\)se1 Yes
Operating System cisco ios 15.0\(2\)se2 Yes
Operating System cisco ios 15.0\(2\)se3 Yes
Operating System cisco ios 15.0\(2\)se4 Yes
Operating System cisco ios 15.0\(2\)se5 Yes
Operating System cisco ios 15.0\(2\)se6 Yes
Operating System cisco ios 15.0\(2\)se7 Yes
Operating System cisco ios 15.0\(2\)se9 Yes
Operating System cisco ios 15.2\(1\)ey Yes
Operating System cisco ios 15.2\(2\)e Yes
Operating System cisco ios 15.2\(2\)e1 Yes
Operating System cisco ios 15.2\(2\)e2 Yes
Operating System cisco ios 15.2\(2\)e4 Yes
Operating System cisco ios 15.2\(3\)ea Yes
Operating System cisco ios 15.3\(3\)ja Yes
Operating System cisco ios 15.3\(3\)ja1 Yes
Operating System cisco ios 15.3\(3\)ja1m Yes
Operating System cisco ios 15.3\(3\)ja1n Yes
Operating System cisco ios 15.3\(3\)ja4 Yes
Operating System cisco ios 15.3\(3\)ja5 Yes
Operating System cisco ios 15.3\(3\)ja7 Yes
Operating System cisco ios 15.3\(3\)ja8 Yes
Operating System cisco ios 15.3\(3\)ja9 Yes
Operating System cisco ios 15.3\(3\)ja77 Yes
Operating System cisco ios 15.3\(3\)jaa Yes
Operating System cisco ios 15.3\(3\)jab Yes
Operating System cisco ios 15.3\(3\)jax Yes
Operating System cisco ios 15.3\(3\)jax1 Yes
Operating System cisco ios 15.3\(3\)jax2 Yes
Operating System cisco ios 15.3\(3\)jb Yes
Operating System cisco ios 15.3\(3\)jb75 Yes
Operating System cisco ios 15.3\(3\)jbb Yes
Operating System cisco ios 15.3\(3\)jbb1 Yes
Operating System cisco ios 15.3\(3\)jbb2 Yes
Operating System cisco ios 15.3\(3\)jbb4 Yes
Operating System cisco ios 15.3\(3\)jbb5 Yes
Operating System cisco ios 15.3\(3\)jbb6 Yes
Operating System cisco ios 15.3\(3\)jbb6a Yes
Operating System cisco ios 15.3\(3\)jbb8 Yes
Operating System cisco ios 15.3\(3\)jbb50 Yes
Operating System cisco ios 15.3\(3\)jc Yes
Operating System cisco ios 15.3\(3\)jn3 Yes
Operating System cisco ios 15.3\(3\)jn4 Yes
Operating System cisco ios 15.3\(3\)jn7 Yes
Operating System cisco ios 15.3\(3\)jn8 Yes
Operating System cisco ios 15.3\(3\)jnb Yes
Operating System cisco ios 15.3\(3\)jnb1 Yes
Operating System cisco ios 15.3\(3\)jnb2 Yes
Operating System cisco ios 15.3\(3\)jnb3 Yes
Operating System cisco ios 15.3\(3\)jnc Yes
Operating System cisco ios 15.3\(3\)jnc1 Yes
Operating System cisco ios 15.3\(3\)jnp Yes
Operating System cisco ios 15.3\(3\)jnp1 Yes

References

How SecUtils Interprets This CVE

SecUtils normalizes and enriches National Vulnerability Database (NVD) records by standardizing vendor and product identifiers, aggregating vulnerability metadata from both NVD and MITRE sources, and providing structured context for security teams. For cisco's affected products, we extract Common Platform Enumeration (CPE) data, Common Weakness Enumeration (CWE) classifications, CVSS severity metrics, and reference data to enable rapid vulnerability prioritization and asset correlation. This record contains no exploit code, proof-of-concept instructions, or attack methodologies—only defensive intelligence necessary for patch management, risk assessment, and security operations.